ZcopyReaper: A Local Privilege Escalation in the Linux Kernel RDS Path
A vulnerability CVE-2026-43502 (ZcopyReaper) has been discovered in the Linux kernel, allowing a local attacker to gain root through the zerocopy send path of the RDS protocol. A fix is available in a kernel update; the patch does not take effect without a reboot.
- CVE-2026-43502 affects zerocopy send path in RDS (Reliable Datagram Sockets)
- Vulnerability allows local user to gain root privileges
- To protect, update kernel and reboot
- The rds module is not needed by most servers and can be blocked
Read next
Security